Tento dokument je k dispozici v angličtině a polštině. Rozhodující je anglická verze.
Privacy Policy
We do not receive your activity data. This policy explains the small amount of data we do handle, why, and for how long.
Last updated: 2026-10-07
The short version
- Bikepark app processes location, speed, altitude, heart rate and other sensor data only on your Garmin watch. The app has no network permission, so it cannot send anything to us or to anyone else.
- When you buy the full version, we receive your e-mail address, order details from Paddle and a short ID shown on your watch. We use them to issue your licence and to help you if something goes wrong.
- This website uses Google Analytics only if you agree to it. There are no advertising cookies, fonts or trackers.
- We do not sell your data and we do not send newsletters.
1. Who is responsible for your data
The controller of your personal data is Marcin Góralski, running a sole proprietorship under the trade name Bikepark app, NIP (tax ID) 9131635809, REGON 525491425. For anything related to your data, write to privacy@bikeparkapp.com.
Bikepark app is an independent third-party application for Garmin devices and is not affiliated with, sponsored by, or endorsed by Garmin Ltd. or its subsidiaries.
2. Data processed on your watch
To detect runs and lifts and record your activity, the app uses on your watch: GPS position and track, altitude and barometric pressure, speed, distance, time, heart rate and other sensor readings, your heart-rate zones from your Garmin user profile, and the runs and lifts it detects.
This processing happens locally on the watch. Bikepark app does not transmit GPS tracks, heart rate or activity data to servers operated by us. The app's Garmin manifest does not request network access, which the watch enforces.
The app keeps on the watch only its settings and a short summary of your last saved session. They stay there until you uninstall the app.
When you save an activity, your watch creates a standard activity file (FIT). Your watch and Garmin Connect then store and synchronise it under your own Garmin account, as with any other activity. Garmin processes that data as an independent controller under its own privacy policy; we never receive it.
3. Data we receive when you buy the full version
Payments are processed by Paddle, which acts as Merchant of Record and is the seller of the order. Paddle collects your payment details; we never see or store your card data. Paddle shares with us only what we need to fulfil the order:
- your e-mail address,
- order and transaction identifiers, product, price, currency, country and payment status,
- the watch ID you enter at checkout,
- information needed to handle refunds and support.
The watch ID. The unlock code is tied to one watch, so at checkout you type a short ID shown on your watch (in the app: Settings, then Licence). It is derived from an identifier that Garmin gives each app on each device. It is different for every app, so it cannot be used to link you across apps, and it is not your watch's serial number. We use it only to generate your unlock code and to handle a licence transfer when you change watches.
The unlock code. We send it to you by e-mail. You enter it in the app's settings in Garmin Connect, and the watch checks it offline. App settings, including the code, are stored and synchronised by Garmin as part of its service.
4. Support messages
If you write to us, we process the content of your message and your e-mail address to answer you.
5. This website
The website uses no advertising tools and loads no third-party fonts. Without your consent we set no cookies.
Our hosting provider keeps standard server logs (IP address, time, requested page, browser type) for security and to keep the site running. When you open the Paddle checkout, Paddle's own privacy notice applies to what you do there.
Google Analytics, only with consent. If you accept statistics in the banner, we load Google Analytics 4 to learn how many people visit, where they come from and which sections they read. Google then sets the cookies _ga and _ga_* and receives information about the visit: pages viewed, device and browser type, and an approximate location derived from the IP address. Google Analytics 4 does not store IP addresses. Without consent the script does not load. You can withdraw consent at any time with the "Cookie settings" link in the footer.
6. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Issuing, delivering and transferring your licence | E-mail, order details, watch ID | Performance of a contract, Art. 6(1)(b) |
| Answering support requests | E-mail, message content, order details | Performance of a contract, Art. 6(1)(b) |
| Accounting and tax records | Order and payout records | Legal obligation, Art. 6(1)(c) |
| Preventing fraud and abuse, handling claims, keeping the site secure | Order details, server logs | Legitimate interest, Art. 6(1)(f) |
| Website visit statistics (only with consent) | Pages viewed, device and browser type, approximate location, cookie identifiers | Consent, Art. 6(1)(a) |
We do not use your data for marketing. If we ever offer a newsletter, it will be opt-in and separate from your purchase.
7. How long we keep data
- Licence and order data: while your licence is in use, then until claims related to it are time-barred (in Poland at most six years).
- Accounting records: for the period required by Polish tax law, currently five years from the end of the year in which the tax became due.
- Support messages: two years after the last message in the conversation.
- Server logs: kept by our hosting provider for a short period, no longer than 30 days.
- Google Analytics data: 14 months, then deleted automatically by Google. Cookies expire after at most 13 months.
- Activity data: we never hold it, see section 2.
8. Who receives your data
- Paddle (Paddle.com Market Limited), the payment provider and Merchant of Record.
- Our hosting and e-mail providers, who process data only on our instructions: SeoHost.pl (SeoHost sp. z o.o., Poland).
- Google Ireland Limited (Google Analytics), only if you consent.
- Authorities, only where the law requires it.
We do not sell or rent personal data.
9. Transfers outside the EEA
Paddle is based in the United Kingdom, which the European Commission recognises as providing an adequate level of protection. Where any provider transfers data further outside the EEA, it does so under safeguards required by the GDPR, such as the Standard Contractual Clauses.
Google may process Google Analytics data in the United States under the EU-US Data Privacy Framework and the Standard Contractual Clauses.
10. Your rights
You have the right to access your data, have it corrected or deleted, restrict or object to its processing, and receive it in a portable format. Write to privacy@bikeparkapp.com; a message such as "Delete my data" is enough. We will answer within one month. We may keep records we are legally required to keep, as described in section 7.
You may also lodge a complaint with a supervisory authority. In Poland it is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl). You can also contact the authority in your own country.
11. Children
The app and this website are not directed at children under 16, and we do not knowingly collect their data.
12. Changes
If what the app or the website does with data changes, we will update this policy before the change takes effect and change the date at the top. This policy stays at the same address: https://bikeparkapp.com/privacy/